VDB
Sign up
HIGH7.1

GHSA-gm62-rw4g-vrc4

Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data

Quick fix

GHSA-gm62-rw4g-vrc4 — ch.qos.logback:logback-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.4.14</version> for ch.qos.logback:logback-core

Details

A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/ch.qos.logback:logback-core
Introduced in: 1.4.13Fixed in: 1.4.14
Fix# pom.xml: bump <version>1.4.14</version> for ch.qos.logback:logback-core
Maven/ch.qos.logback:logback-core
Introduced in: 1.3.13Fixed in: 1.3.14
Fix# pom.xml: bump <version>1.3.14</version> for ch.qos.logback:logback-core
Maven/ch.qos.logback:logback-core
Introduced in: 1.2.12Fixed in: 1.2.13
Fix# pom.xml: bump <version>1.2.13</version> for ch.qos.logback:logback-core

References